Protecting Cookies with Device Bound Session Credentials
2026-04-09T19:23:43Z•e5299e634c270fc0c20b66ba82456711734077e2a6911da3b650622921d22d7f
AndroidAndroid 17Certificate TransparencyChrome 146DBSCDevice Bound Session CredentialsGeminiIPILLM securityLummaC2MTCMerkle Tree CertificatesPLANTS IETF working groupPQCVRPVulnerability Rewards ProgramWindowscookie theftindirect prompt injectioninfostealermacOSpost-quantum cryptographyprompt injectionquantum-safe HTTPSsession hijacking
What happened
This collection of Google Security Blog posts (Mar–Apr 2026) announces multiple defensive and roadmap updates: Device Bound Session Credentials (DBSC) is now publicly available for Windows in Chrome 146 (with macOS coming soon) to proactively prevent cookie/session theft by tying session credentials to a device and making exfiltrated cookies unusable; Google Workspace is adopting continuous mitigations against indirect prompt injection (IPI) targeting LLMs and agentic automation; Google published a VRP (Vulnerability Rewards Program) 2025 year-in-review; Android will begin tests of Post‑Quantm
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- google_security_blog
- Record identifier
- e5299e634c270fc0c20b66ba82456711734077e2a6911da3b650622921d22d7f
- Enrichment time
- 2026-04-09T19:23:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.